CISA Domain 2B-1 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain B-1 (Resource Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2B-1 IT Resource Management Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor is reviewing IT resource management at a regional bank. IT personnel are assigned to initiatives reactively based on who is available, and there is no capacity plan linking staffing to the approved project portfolio. Which of the following should concern the auditor MOST?
    Question 2
    During an audit of a government agency's IT function, the auditor wants to determine whether IT human and infrastructure resources are aligned with the agency's multi-year strategic objectives. The agency recently launched a large digital services program. Which of the following would provide the BEST evidence?
      Question 3
      An IS auditor examining a healthcare provider's IT resource management notes that several critical clinical systems depend on a single administrator with highly specialized skills, and no skills inventory or succession plan currently exists for that key role. What should the IS auditor do FIRST?
        Question 4
        An audit of an energy utility's IT operations finds that specialized servers purchased for a cancelled initiative now sit idle, while other teams separately procure additional cloud capacity to meet their processing demand. Which recommendation is MOST appropriate to improve IT resource utilization across the organization?
          Question 5
          An IS auditor reviews IT resource management at an insurance company and finds that no single function owns the allocation of shared IT resources; instead, each business unit negotiates directly with individual IT teams for the capacity it needs. Which of the following is the auditor's GREATEST concern?
            Question 6
            An IS auditor wants to determine whether an online retailer's IT capacity and resource planning will be effective ahead of a demanding peak sales season. The retailer experienced capacity-related outages during the previous holiday period. Which audit procedure would provide the MOST reliable assurance that resource planning is working as intended?
              Question 7
              A telecommunications company outsources part of its IT development to reduce its growing reliance on scarce internal technical skills. The IS auditor is evaluating whether this sourcing decision supports the organization's IT resource management objectives. Which factor is MOST important for the auditor to assess?
                Question 8
                During a review of a public university's IT resource management, the auditor finds that IT budget and headcount are allocated each year using the prior year's figures, without reference to current project demand, service levels, or the institution's strategic plans. Which finding is MOST significant?
                  Question 9
                  Following an audit that recommended a formal IT resource capacity plan, an IS auditor conducts a follow-up review at a logistics firm. Management states that the plan is still 'in progress' but provides no documentation. What is the auditor's BEST course of action at this point?
                    Question 10
                    An IS auditor evaluates a control requiring that all IT resource requests be approved through a centralized demand-management process aligned to the IT portfolio. Which of the following would provide the BEST assurance that this control is operating effectively throughout the entire period under review?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top